
FirmAE
Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

Read out-of-bounds PoC for miniupnpd <= v2.1


Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…


CVE-2025-22912

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.


CVE-2018-19537

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…


Exploit for CVE-2021-27342 vulnerability (telnet authentication brute-force protection bypass)

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

A PoC for CVE-2025-67445

Security advisory for CVE-2025-65855 - Multiple vulnerabilities in HelpFlash IoT OTA update mechanism